CVE-2026-16745: Red Hat Openshift Ai 2.25

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.

Affected products

  • Red Hat Red Hat Openshift Ai 2.25: before 1785940823 (fixed in 1785940823); before 1788312226 (fixed in 1788312226)
  • Red Hat Red Hat Openshift Ai 3.3: before 1786109683 (fixed in 1786109683); before 1790128681 (fixed in 1790128681)
  • Red Hat Red Hat Openshift Ai 3.4: before 1786109665 (fixed in 1786109665); before 1787347991 (fixed in 1787347991)

Published 2026-07-23. Last modified 2026-09-30.